Google Search

Showing posts with label Steal. Show all posts
Showing posts with label Steal. Show all posts

Friday, March 15, 2013

Anatomy of a phish - how crooks hack legitimate websites to steal your details

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Old-school phishing is where cybercrooks lure you into logging in to your bank account on one of their websites.

When you enter your personally identifiable information (PII), as you would on the bank's real site, it gets uploaded to the crooks instead of to your bank.

The idea, of course, is that they then use the credentials they just stole to start draining your account.

So phishing is still worthwhile to the crooks, even though it doesn't seem to be quite as successful as it used to be. Many of us have learned to take great care when we're banking online, and to check for the "vital signs" of a scam before we trust a website with our usernames and passwords.

Nevertheless, the phishers are still giving it all they've got. By combining simplicity with accuracy, they're creating banking scams that are much more believable than the crude and misspelled emails and websites that were common a few years ago.

If you pick your moment, or just get lucky, there's still money to be made.

In Australia, for example, today (at least in Sydney) has been a very wet and gloomy public holiday.

Just the sort of morning to loaf on the couch with your laptop or your iPad and goof off online, where you might have received an email like this one:

Many banks now have a closed cloud-style email service built into their internet banking sites. The idea is that you'll get into the habit of logging in securely to read important messages, rather than believing what arrives in insecure emails.

The bank still sends you emails, but they don't contain any detail - they just give you an overview (e.g. "your statement is ready"), and advise you to read the full message on the secure site. A bit like the message here, in fact.

But what your bank won't do is to invite you to click a link to get to the secure site. They rightly leave you (indeed, they urge you) to find your own way to the banking portal, so you're not at the mercy of the URL embedded in the email.

So the link here is certainly phishy - it shouldn't be present at all - but it doesn't look like the sort of obvious phishing nonsense you often see.

You probably know what I mean: weird and unlikely domains such as really.your.bank.wefljdrsecxr.example.org that are an instant giveaway of bogosity.

In fact, this phish links to a government website in .cn (that the People's Republic of China, or PRC):

The government site seems to have had a security lapse, allowing the crooks to add a small and simple web page called nabau.html.

This page silently redirects your browser elsewhere by using this HTML:

The redirect takes you off to another hacked site, specified in the URL as an IP number rather than as a domain name.

This presents you with a bogus login page hosted on a web server (it looks like part of the Computer Science department) at a Colombian university:

Ironically, this bogus page helpfully advises you to keep up to date with anti-virus, firewall software and the latest patches, and urges you to report phishing scams to NAB.

When you click Login to submit the form, the POST request (HTTP's name for an upload) goes to yet another hacked web property. This one is a student vacation site in the USA, apparently with some insecure plugins in its blogging subdirectories.

You never get to see the site's main page, which is unexceptional:

Instead, the web upload that is linked to from from the Colombian university page gives the crooks their first page of login data.

Then you're shuffled back to the server in Colombia to face a request for another page of PII:

The POST request on this page uploads your formful of data to the same place as before: the US student vacation site.

This time, the vacation site bounces you back to Australia, rounding off the phishers' journey.

You end up unremarkably on National Australia Bank's own site, albeit that you're on the regular main page, not amongst the internet banking pages:

Let me be quick to say that you ought not to fall for this sort of phish:

NAB wouldn't have put a link in the email, so you ought not to have clicked it.None of the so-called banking sites referenced a nab.com.au URL.None of them used secure HTTP, also known as HTTPS.

(HTTPS is the protocol that puts a tiny padlock in the address bar at the top of your browser's screen.)

Nevertheless, this phish didn't take you to any sites that would have stood out, under normal circumstances, as part of the cybercriminal underworld.

It relied on three unremarkable and legitimate servers, owned by legitimate organisations and operated by unsuspecting sysadmins, in three different countries: PRC, Colombia and the USA.

That's why even self-proclaimed "safe surfers" - people who back themselves not to wander off into obviously-shady parts of the web - should consider themselves at risk.

Be careful out there. And that applies whether you're browsing or running an online business.

The crooks want to redirect your browser into harm's way, and they want to use your servers to help them do so.

Follow @duckblog

Running a web server at home?

Why not try out the free Sophos UTM Home Edition?

You get web and email filtering, web application firewall, IPS, VPN and more for up to 50 IP addresses. You can also protect up to 12 Windows PCs on your network with Sophos Anti-Virus!

(Note: registration required.)


View the original article here

Tuesday, January 22, 2013

But did she STEAL the iPhone? App takes photo of woman trying to unlock it

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

iGotYaA woman who tried to unlock a stolen iPhone unwittingly took her own photo. An app on the phone then automatically sent the photo to the owner, who called the police.

The app, identified by some media outlets as iGotYa, can only be installed on jailbroken iPhones.

iGotYa takes a picture of anyone who tries to unlock it, maps their location and then sends the information to the owner in an email.

That's exactly what happened in this particular case, Sussex Police said, with an iPhone that had been stolen from the Coalition nightclub in Brighton, East Sussex, earlier this month.

Police have released the picture of the woman who might have stolen the phone.

iPhone capture, courtesy of Sussex Police

The Huffington Post quoted Pc Gavin Crute, of Sussex Police, as saying that they're eager to talk to the woman or anyone who might recognise her:

"We know where and when the photo was taken, and it appears to be in a vehicle with quite a large sunroof."

"We don't know that the woman is the person who stole the camera, but she obviously has had some connection with it in the meantime, and I'd like to speak to her about it."

Of course, not everyone wants to jailbreak their iPhones.

Fortunately, there are other ways to protect either an iPhone or an Android, as Naked Security outlines here.

Switching on a smartphone's GPS tracking function can help, and you can do that with either Apple's Find my iPhone app or, for Androids, Sophos's free Mobile Security app.

The cost of the phone is only one thing to worry about when it comes to losing a pricey smartphone, of course. Loss of data is another thing entirely.

Sophos Mobile SecurityWhich is another reason to use one of these or similar applications: Either Find my iPhone or Sophos Mobile Security will remotely wipe data in case of theft or loss.

Many such applications include additional features such as protection from malware.

An enterprise edition of Sophos's free app, called Sophos Mobile Control, also allows you to:

Enforce your security policies to ensure complianceTurn on the built-in security features of iOS (iPhone/iPad), Android, BlackBerry and Windows Mobile devices, including password protection or any iOS encryption.Ensure that only registered devices that meet your policies - i.e., not rooted (Android) or jailbroken (iOS) - have full access to corporate data and that the users of non-compliant devices are blocked or face other consequences until the situation is rectified.Help locate, lock or wipe lost devices, from the admin web console or the self-service portal.Have an immediate overview of your company's device status from the security dashboard.Prove your corporate compliance with easy inventory and reporting tools.

You do need an app like iGotYa to take an automatic snapshot of people trying to unlock your device, though.

Whichever route you pick - free app, paid app that lets you snap photos of people trying to unlock your phone, or enterprise app with more features - is better than leaving that precious gadget stark naked, unprotected and untrackable.

In the meantime, if you recognise the woman in the photo, Sussex Police ask that you call it in. In England, dial your local police on their non-emergency number: 101.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Thursday, August 30, 2012

Hackers get into AMD and steal over 30,000 - wait for it - BYTES!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A hacker calling himself r00tbeer, supposedly representing a four-strong hacker group calling itself r00tbeersec, has announced on Twitter a hack of chip vendor and Intel rival AMD.

After bragging just over a day ago that "our next target will be a large company, stay tuned for the upcoming database dump," the mighty hackers lived up to their promise. Earlier today they leaked a complete SQL database dump totalling nearly thirty-two KB.

(Yes. You read that correctly. It's just under 32 kilobytes in the new measuring system, and just over 30 kibibytes, as today's youth - who wouldn't know a power of two if it chopped them in half - like to call the old units.)

It's a SQL database of 189 usernames and and what look like PHPass-hashed passwords, apparently retrieved by foul means from AMD's WordPress-driven blog site.

185 of the usernames are accompanied by email addresses, of which 174 are from AMD and most of the rest from two PR companies, edelman.com and bitecommunications.com. A reminder to the PR guys: if you work on the AMD account and you've been using the same password on other sites, stop doing that!

A few of the records also include an intriguing - but unexplained - field called user_activation_key. Whatever those are, it would be a good idea for AMD to deactivate them and issue new ones.

All in all, a small deal in the history of security breaches. More of a hackette than a hack, and no AMD customers need to panic, which is good news.

But every hack is, at its heart, bad news.

If only we were collectively more conscientious about patching against criminals, and if only those criminals were more likely to be caught!

Of course - since, where hacking is concerned, an injury to one is an injury to all - the vast majority of Internet Good Guys amongst us can help make both those things come true.

Patch early. Patch often. Keep logs. Report breaches.

Here's some frank talk to tell you why:

(Duration 15'25", size 11MBytes)

Follow @duckblog
-


View the original article here

Friday, July 1, 2011

Hackers Steal Info on Military, Defense Personnel

Email addresses and names of subscribers to DefenseNews, a highly-regarded website that covers national and international military and defense news, were accessed by hackers and presumed stolen, Gannett announced yesterday.

DefenseNews ' subscribers include active and retired military personnel, defense contractors and others in both the U.S. and other countries' defense establishments.

"We discovered that the attacker gained unauthorized access to files containing information of some of our users," said Gannett Government Media, an arm of the media chain that publishes not only DefenseNews, but also the Military Times and Federal Times sites, as well as a number of military-specific magazines and journals, ranging from the Army Times to the Intelligence, Surveillance and Reconnaissance Journal.

In a message posted to its site Monday , Gannett acknowledged that the accessed information included first and last names, email addresses, account passwords, and duty status branch of service for military personnel.

Gannett urged registered users to reset their site passwords, "as well as your other online accounts, particularly those that use the same email address used for your Gannett Government Media Corporation account."

The attack was first detected June 7.

One security expert said it was possible the attack against DefenseNews and the other sites Gannett operates was targeted, perhaps by state-backed hackers. "It's hard to know if this was just part of the general ransacking of sites, or an attempt to obtain valuable information for spear-phishing," said Anup Ghosh, the founder and CEO of Web security firm Invincea.

Ghosh said it's likely the attack was deliberately after the names and email addresses of people in the defense industry and military.

"This is a pretty selective group," Ghosh said of the DefenseNews account holders, and would be restricted in scope to the military-industrial [establishment]. It would be very attractive from a nation-state point of view."

He based the last observation on the fact that hackers-for-profit are unlikely to go after such names and addresses. "But nation-state [hackers] are after military and defense intellectual property, and designs and plans."

The stolen information would make the perfect fodder for future "spear phishing," the kind of attacks that target individuals within an organization by crafting convincing messages, often with embedded links or attached files that direct recipients to malicious sites or plant malware directly on PCs to, for instance, gather more information or gain greater access to a network.

Spear phishing attacks have been blamed for a number of recent high-profile attacks, including ones against the International Monetary Fund (IMF) and senior government officials through Gmail.

Military contractors, most notably Lockheed , have also been attacked this year, although not necessarily through spear-phishing tactics.

"With this information, spear phishers could create pretty convincing messages [to these individuals]," said Ghosh, who said that click-through rates in such attacks can reach as high as 20%, meaning one-out-of-five people click on a link, open a file attachment or disclose other personal information.

Ghosh also noted that defense agencies and militaries are careful not to reveal contact information for their workers or personnel, for just that reason. "I wouldn't have thought to target a publication like this," said Ghosh. "It was actually very clever."

Gannett has sent emails to subscribers whose information was accessed, and warned them against falling for any spear phishing schemes.

"You should delete any unusual or suspicious emails without opening them and should not click on any links embedded in a message that appears suspicious once you have opened it," the company told subscribers in a copy of the email obtained by Computerworld.

DefenseNews has not said how many account records were accessed by attackers, and did not return a call for comment Tuesday.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is gkeizer@computerworld.com .

Read more about cybercrime and hacking in Computerworld's Cybercrime and Hacking Topic Center.

Computerworld
For more enterprise computing news, visit Computerworld. Story copyright © 2011 Computerworld Inc. All rights reserved.


View the original article here